UTSA team wants companies and governments to adopt a scientific framework to measure cyber agility.
(June 7, 2019) –- For more than a year, GozNym, a gang of five Russian cyber criminals, stole login credentials and emptied bank accounts from unaware Americans. To detect and quickly respond to escalating cyber-attacks like these, researchers at The University of Texas at San Antonio (UTSA) have developed the first framework to score the agility of cyber attackers and defenders. The cyber agility project was funded by the Army Research Office.
“Cyber agility isn’t just about patching a security hole, it’s about understanding what happens over time. Sometimes when you protect one vulnerability, you expose yourself to 10 others,” said computer science alumnus Jose Mireles ’17, who now works for the U.S. Department of Defense and co-developed this first known framework as part of his UTSA master’s thesis. “In car crashes, we understand how to test for safety using the rules of physics. It is much harder to quantify cybersecurity because scientists have yet to figure out what are the rules of cybersecurity. Having formal metrics and measurement to understand the attacks that occur will benefit a wide range of cyber professionals.”
To develop a quantifiable framework, Mireles collaborated with fellow UTSA student Eric Ficke, researchers at Virginia Tech, U.S. Air Force Research Laboratory, and the U.S. Army Combat Capabilities Development Command Army Research Laboratory (CCDC ARL). The project was conducted under the supervision of UTSA Professor Shouhuai Xu, who serves as the director of the UTSA Laboratory for Cybersecurity Dynamics.
Together, they used a honeypot—a computer system that lures real cyber-attacks—to attract and analyze malicious traffic according to time and effectiveness. As both the attackers and the defenders created new techniques, the researchers were able to better understand how a series of engagements transformed into an adaptive, responsive and agile pattern or what they called an evolution generation.
The framework proposed by the researchers will help government and industry organizations visualize how well they out-maneuver attacks. This groundbreaking work will be published in an upcoming issue of IEEE Transactions on Information Forensics and Security, a top cybersecurity journal.
“The cyber agility framework is the first of its kind and allows cyber defenders to test out numerous and varied responses to an attack,” said Xu. “This is an outstanding piece of work as it will shape the investigation and practice of cyber agility for the many years to come.”
"The DoD and US Army recognize that the Cyber domain is as important a battlefront as Ground, Air and Sea," said Purush Iyer, Ph.D. division chief, network sciences at Army Research Office, an element of CCDC ARL. "Being able to predict what the adversaries will likely do provides opportunities to protect and to launch countermeasures."
Mireles added, “A picture or graph in this case is really worth more than 1,000 words. Using our framework, security professionals will recognize if they’re getting beaten or doing a good job against an attacker.”
UTSA is home to the nation’s top cybersecurity program, an interdisciplinary approach that spans three colleges: the College of Business, College of Engineering and College of Sciences. Research centers and outreach programs provide UTSA students and faculty with additional opportunities to explore the various facets of this high demand and ever-changing field.
The Department of Computer Science, housed in the UTSA College of Sciences, offers bachelor’s, master’s and doctoral degree programs that support more than 1,360 undergraduate students and 68 graduate students. Its major research units include the UTSA Institute for Cyber Security, which operates the FlexCloud and FlexFarm laboratories dedicated to both basic and applied cybersecurity research, and the UTSA Center for Infrastructure Assurance and Security (CIAS), which focuses on the cybersecurity maturity of cities and communities while conducting national cyber defense competitions for high school and college students.
San Antonio is home to one of the largest concentrations of cybersecurity experts and industry leaders outside Washington, D.C., which uniquely positions the city and UTSA to lead the nation in cybersecurity research and workforce development.
Learn more about the UTSA Department of Computer Science.
Learn more about cybersecurity at UTSA.
Celebrate UTSA’s 50th Anniversary and share social media posts about the 50th using the hashtag #UTSA50.
Connect with UTSA online at Facebook, Twitter, YouTube, Instagram and LinkedIn.
UTSA Today is produced by University Communications and Marketing, the official news source of The University of Texas at San Antonio. Send your feedback to news@utsa.edu. Keep up-to-date on UTSA news by visiting UTSA Today. Connect with UTSA online at Facebook, Twitter, Youtube and Instagram.
Have questions about making your OER accessible on UTSA Pressbooks? The OER Team and the Digital Accessibility are ready to answer them! Bring your questions about OER and accessibility and receive guidance from our two teams.
Virtual (Zoom)Perfect for faculty and grad students who are ready to take their research to the next level, this workshop will guide you through the basics of the I-Corps program. Learn how I-Corps can teach you entrepreneurial skills to translate your research to commercialization, how you can get funding to discover customers for your technology, and how I-Corps can help you find the value proposition that will get your technology to sell. Lunch is included.
TBDLearn how to maximize the benefits of ORCID, how it can help you save time, and how to set up automatic updates to keep your ORCID record current.
Virtual Event (Zoom)In this hands-on workshop, participants will learn to setup an EndNote library, save references and PDFs, and automatically create and edit a bibliography. Attendees are encouraged, but not required, to have EndNote already installed on a personal computer.
Virtual Event (Zoom)Pressbooks Basic workshop attendees will be able to: create a new book, clone an existing book, remix chapters from a variety of different Creative Commons licensed books, add media and other content to a book, export a book in a wide range of formats.
Virtual (Zoom)This workshop will guide you how to leverage Overleaf program to effectively manage citations in your research papers.
Virtual Event (Zoom)This event, hosted by Rackspace Government Solutions, promises to be an insightful and engaging opportunity to explore the ethical, practical and transformative applications of AI technology in educational and public institutions.
University Room (BB 2.06.06,) Business Building, Main CampusThe University of Texas at San Antonio is dedicated to the advancement of knowledge through research and discovery, teaching and learning, community engagement and public service. As an institution of access and excellence, UTSA embraces multicultural traditions and serves as a center for intellectual and creative resources as well as a catalyst for socioeconomic development and the commercialization of intellectual property - for Texas, the nation and the world.
To be a premier public research university, providing access to educational excellence and preparing citizen leaders for the global environment.
We encourage an environment of dialogue and discovery, where integrity, excellence, inclusiveness, respect, collaboration and innovation are fostered.
UTSA is a proud Hispanic Serving Institution (HSI) as designated by the U.S. Department of Education .
The University of Texas at San Antonio, a Hispanic Serving Institution situated in a global city that has been a crossroads of peoples and cultures for centuries, values diversity and inclusion in all aspects of university life. As an institution expressly founded to advance the education of Mexican Americans and other underserved communities, our university is committed to promoting access for all. UTSA, a premier public research university, fosters academic excellence through a community of dialogue, discovery and innovation that embraces the uniqueness of each voice.